(I assume you have some reason for not just passing a session key in the URL and keeping all the relevant state on the server.)
(I assume you have some reason for not just passing a session key in the URL and keeping all the relevant state on the server.)